MALICIOUS — 57017996172.pdf
MALICIOUS — 57017996172.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8c114a26d2273a8f5bbe04aa2592e051c9018c4ac4c162a04c32f070e2e8d20c - SHA-1:
2c2e4e43952ca9da89770288b95cbd51cdcd6108 - MD5:
58cbad86575625b38c77f4f790d5b5aa - ssdeep:
1536:uLClGtDcRINI60/Hsx70p38uB9NYhAIFaxGstkrL/p2wG:VGpBxYpX7NYAQ4kxG - TLSH:
T12D37CFE362CBEDCC77899B43B5B7251D14D5C78D6133AA200488673CC9B86EEEE00921 - Submitted as: 57017996172.pdf
- File type: pdf · Size: 73768 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!58CBAD865756
- Kaspersky (KVRT): HEUR:Hoax.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://dc58184e-bbba-402a-8e08-a55d552c8f3f.filesusr.com/ugd/0ebc1f_46ab4e957ae24687a1f199b914ff43ae.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://jumiwimov.ru/strik?utm_term=the+book+pdf+download, https://cdn.sqhk.co/saboxiwago/hajcbie/ninja_masters_codes_list.pdf, https://cdn.sqhk.co/gawivoxolo/7Oyjegc/aiken_regal_movie_theatre_showtimes.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jumiwimov.ru/strik?utm_term=the+book+pdf+download
- https://cdn.sqhk.co/saboxiwago/hajcbie/ninja_masters_codes_list.pdf
- https://cdn.sqhk.co/gawivoxolo/7Oyjegc/aiken_regal_movie_theatre_showtimes.pdf
- https://dc58184e-bbba-402a-8e08-a55d552c8f3f.filesusr.com/ugd/0ebc1f_46ab4e957ae24687a1f199b914ff43ae.pdf?index=true
- https://cdn.sqhk.co/mudifuto/djgkqjh/chores_in_spanish_slang.pdf
- http://eduha.online/rovuwedojekabawifemuseoxc7i.pdf
- https://cdn.sqhk.co/tuminageka/z04jgjd/childrens_words_that_begin_with_gr.pdf
- http://shopsmmv.site/korean_vocabulary_list_by_topickl602.pdf
- https://cdn.sqhk.co/wesegagage/jcSrXqr/affirmation_synonyms_and_antonyms.pdf
- http://muparizuxufuxud.22web.org/formative_assessment_in_higher_education.pdf
- https://uploads.strikinglycdn.com/files/b653ba55-39db-4862-97df-5d7d09dab8a3/lazukilun.pdf
- https://05e27880-d5e1-4d3d-8428-ba943e9300bc.filesusr.com/ugd/b56239_71fb9dc1439744fcafb2024e70490136.pdf?index=true
- https://cdn.sqhk.co/sipebililofo/igQzJic/mejesiwunowil.pdf
- https://cdn.sqhk.co/nivopekodi/ijcieyy/nemor.pdf
- http://islemleriniz.org/56771213966y08wn.pdf
- https://cdn.sqhk.co/noloxunipe/gja576T/mini_rc_racing_drone.pdf
- https://4c6480a9-ccec-4c20-853c-cc48681c44ad.filesusr.com/ugd/935adc_eb5e728c75d64d8792af9e42d64a13e6.pdf?index=true
- http://derabipolo.rf.gd/73829911934.pdf
- https://uploads.strikinglycdn.com/files/bc743309-ef05-4717-93e7-e1e126eaefac/buffalo_wzr-600dhp2_firmware_download.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- jumiwimov.ru
- cdn.sqhk.co
- dc58184e-bbba-402a-8e08-a55d552c8f3f.filesusr.com
- eduha.online
- shopsmmv.site
- muparizuxufuxud.22web.org
- uploads.strikinglycdn.com
- 05e27880-d5e1-4d3d-8428-ba943e9300bc.filesusr.com
- islemleriniz.org
- 4c6480a9-ccec-4c20-853c-cc48681c44ad.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- derabipolo.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report